Context
As a Business Information Security Officer for a large health-services organization, I owned cybersecurity GRC for roughly 150 applications, including 30 business-critical systems handling PHI, PII, or PCI DSS data. When I picked up the portfolio, remediation SLA compliance sat at about 65%.
The challenge
A 65% compliance rate meant roughly a third of findings were missing the timeframes the organization had committed to. Findings aged out quietly, risk acceptances accumulated without review, and there was no reliable rhythm for getting overdue items in front of the people who could act on them. The scanning was not the problem. The follow-through was. Nobody owned the gap between a finding being identified and a finding being closed, so it sat.
What I did
- Established a recurring review cadence. I set up regular remediation reviews with application and business owners, so overdue and upcoming findings surfaced on a predictable schedule rather than in a scramble at deadline.
- Rebuilt exception and risk-acceptance tracking. Every accepted risk was given an owner, a documented rationale, and an expiry, so nothing could be parked indefinitely. I have written more about governing exceptions so they do not become a rubber stamp, and this was where that discipline paid off.
- Created a clear escalation path. For items that stalled, I built a route to senior leadership with the business impact and control concern stated plainly enough for a non-security executive to make the call.
- Reported by severity and by owner. I reported SLA status broken out by severity and by the team that owned each finding, monthly to senior directors and quarterly to VPs, so trends and accountability drove the conversation rather than a single org-wide number.
- Drove remediation to closure. I owned driving the work to completion while the application teams executed the fixes, tracking each item to a documented close.
Outcome
SLA compliance rose from about 65% to about 99% and held there. Aged findings and unreviewed risk acceptances fell sharply, and the compliance figure became a number leadership trusted, because it measured whether the organization kept the commitments it had made rather than how much noise the scanner produced.
What it demonstrates
Running an enterprise vulnerability-remediation program to hit its commitments through ownership, review cadence, exception governance, and executive reporting, across a large portfolio of regulated, business-critical applications. For the general thinking behind the metrics used here, see vulnerability metrics leaders can act on.